A vulnerability categorized as very critical has been discovered in Oracle Enterprise Manager Ops Center 12.4.0.0. This vulnerability affects unknown code of the component User Interface. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2021-40438. The attack can be executed remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Oracle HTTP Server 12.2.1.3.0/12.2.1.4.0/12.2.1.5.0. It has been rated as critical. The impacted element is an unknown function of the component OSSL Module. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2021-40438. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
A vulnerability was found in Apache HTTP Server up to 2.4.46 and classified as problematic. This impacts an unknown function of the component MergeSlashes Handler. Such manipulation leads to Remote Code Execution.
This vulnerability is listed as CVE-2021-30641. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Apache HTTP Server up to 2.4.48. Affected by this issue is some unknown functionality of the component mod_proxy. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2021-40438. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Mozilla Firefox, Firefox ESR and Thunderbird. The impacted element is an unknown function. Performing a manipulation results in memory corruption.
This vulnerability is reported as CVE-2021-38493. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Oracle Agile Product Lifecycle Management for Process 6.2.4. This affects an unknown part of the component Supplier Portal. Executing a manipulation can lead to Remote Code Execution.
This vulnerability appears as CVE-2026-21969. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability categorized as critical has been discovered in Tenda AC5, AC6, AC7, AC9, AC10, AC1206 and FH1205. This issue affects the function formSetSpeedWan. The manipulation of the argument speed_dir results in stack-based buffer overflow.
This vulnerability was named CVE-2023-38936. The attack needs to be approached within the local network. There is no available exploit.
A vulnerability identified as critical has been detected in Tenda AC5, AC6, AC7, AC8, AC9, AC10 and AC1206. Impacted is the function formSetVirtualSer of the component Parameter Handler. This manipulation of the argument list causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2023-38937. The attack needs to be done within the local network. There is no exploit available.
A vulnerability classified as critical was found in Tenda F1202 and FH1202 1.2.0.9. This affects the function formWrlsafeset. Such manipulation of the argument mit_ssid leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2023-38939. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability marked as critical has been reported in Tenda F1202, FH1202, PA202 and PW201A. This affects an unknown part of the file /L7Im. This manipulation of the argument page causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2023-38938. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Tenda AC5, AC8, AC9, AC10 and AC1206. It has been rated as critical. This vulnerability affects the function formSetQosBand of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-38935. The attack can only be initiated within the local network. No exploit exists.